Trove of Stolen Sensitive FBI Employee Data Is Significant Intelligence Risk


Hackers from the group ShinyHunters claim to have stolen personal data of “all” FBI employees and applicants, according to a report published Tuesday by 404 Media.

The group, which was also behind a breach that disrupted software used by 9,000 schools during final exams in May, reportedly gained access to the FBI’s recruitment site via an exploit in Oracle’s PeopleSoft product. ShinyHunters says it now has sensitive data on individuals who applied for FBI jobs as well as current employees, according to 404 Media. ShinyHunters couldn’t be reached for comment.

As of Wednesday afternoon, the apply.fbijobs.gov site shows a maintenance page reading, “We’re sniffing out site updates for you!” The main FBI Jobs home page serves up a “503 Service Temporarily Unavailable” error page. The bureau’s page highlighting eligibility for new applicants is live with a “System Unavailable” banner reading, “Apply.fbijobs.gov and the Special Agent Application Portal are currently unavailable.”

FBI Jobs website screenshot showing two dogs and the headline "Scheduled Maintenance Underway. We're sniffing out site updates for you!"
The FBI’s jobs website shows a maintenance page following a breach by hackers who claim to have stolen sensitive personnel records.Screenshot by Jeff Carlson/CNET

“The FBI is aware of a cyber-criminal enterprise group claiming a compromise of the FBIJobs.gov portal and alleged impact to FBI employee personally identifiable information,” a spokesperson for the FBI told CNET via email. “While the point of breach is still undetermined — whether a third-party or the FBI’s enterprise — we are actively and aggressively investigating this matter and working closely with those third-party providers that support FBIJobs.gov to mitigate any and all risk.”

ShinyHunters has been linked to numerous ransomware attacks, including a breach of 4.4 million TransUnion credit records and access to servers belonging to Rockstar Games, the developer of the Grand Theft Auto series. The group usually demands extortion payments to prevent it from leaking the stolen information.

However, the attack on the FBI’s data is different and has potentially much more serious implications.

The group reportedly wants the FBI to correct what it calls false allegations in a Public Service Announcement that the FBI issued about it. The report notes that ShinyHunter “actors commonly use harassment strategies, sending threatening text messages and phone calls to victims and their family members, and in some cases swatting.”

In an email to The New York Times, a representative of ShinyHunters wrote, “We reiterate we are not extorting the FBI and this is not financially motivated… Our intention, goal and motive is to solely set the record straight.”

But the nature of the stolen data elevates this breach beyond corporate extortion.

Joseph Cox, who broke the story at 404 Media, wrote via email, “This data presents significant national security and counterintelligence risks, and isn’t in the hands of a foreign intelligence agency, but a group of likely younger, English-speaking hackers.”

A security analyst who asked to remain anonymous to avoid retaliation from the hacking group reiterated that this is a serious national security issue. “Remember, the FBI is tasked with both counterespionage and counterterrorism,” they said. “This could destroy [FBI employees’ ability] to go undercover, travel to other countries and more,” including threats to individuals and families.

Asked about the group’s claim that it has nothing to do with extortion, the analyst said, “Never trust anything they say. Ever.”

They said that advice also comes directly from colleagues who advise companies on how to handle the extortions. Gaining access to such sensitive data could be monetarily valuable to a state-level intelligence agency.

The FBI has seen other notable cyberattacks this year, including “suspicious activities” on the system the bureau uses to manage wiretapping and surveillance and claims by an Iran-backed group said to breach the personal email of FBI Director Kash Patel.



Source link

  • Related Posts

    FBI rushes to investigate if ShinyHunters hack of thousands of employees is real

    To get the advisory changed, ShinyHunters told FBI director Kash Patel and the assistant director of the FBI Cyber Division, Brett Leatherman, that they had one week to comply with…

    Continue reading
    Meta VR Glasses, Ray-Ban Meta Audio, Ray-Ban Meta Gen 3: Specs, Features, Prices

    After months of controversy about the privacy of its smart glasses, Meta has unveiled the next iteration of its product lineup. At its Meta Connect event in Menlo Park, CEO…

    Continue reading

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    FBI rushes to investigate if ShinyHunters hack of thousands of employees is real

    FBI rushes to investigate if ShinyHunters hack of thousands of employees is real

    Trump rolls out the red carpet for China’s Xi

    Trump rolls out the red carpet for China’s Xi

    Kentucky State player from Senegal in ICE custody since August

    Kentucky State player from Senegal in ICE custody since August

    AGI Announces Proposed Debenture Amendments

    World of Warcraft Would Never Work on PS5 or Xbox

    World of Warcraft Would Never Work on PS5 or Xbox

    Meta VR Glasses, Ray-Ban Meta Audio, Ray-Ban Meta Gen 3: Specs, Features, Prices

    Meta VR Glasses, Ray-Ban Meta Audio, Ray-Ban Meta Gen 3: Specs, Features, Prices